Hello dear community,
We're trying to create a security policy regarding the installation of plugins from the marketplace on jira on-premise server.
1. Can someone confirm my assumtion that plugins run within the jvm on the server?
2. What about updates, can any author issue an update to their plugin and it will auto update on my server? or is it an elective process?
3. Does anyone knows if any malicious plugin incidents?
4. Does anyone knows if plugins where ever used as an attack vector?
Thanks in advance, community!